devise
Flexible authentication solution for Rails with Warden
Activity
- Latest release
- 4mo ago
- Total releases
- 173
- Cadence
- ~40 days
- Last 12 months
- 6
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 21, 2009
| Version | Released | |
|---|---|---|
5.0.4
patch
| ||
5.0.3
patch
1 CVE
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.2
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
5.0.1
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
5.0.0
major
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
5.0.0.rc
pre
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.9.4
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.9.3
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.9.2
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.9.1
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.9.0
minor
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.8.1
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.8.0
minor
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.7.3
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.7.2
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.7.1
patch
2 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev | ||
4.7.0
minor
3 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.6.2
patch
3 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.6.1
patch
3 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.6.0
minor
3 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.5.0
minor
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.4.3
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.4.2
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.4.1
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.4.0
minor
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.3.0
minor
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.2.1
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.2.0
minor
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.0.3
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.10
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.1.1
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.1.0
minor
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.0.2
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.9
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.0.1
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.8
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.7
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.0.0
major
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.0.0.rc2
pre
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
4.0.0.rc1
pre
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.6
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.5
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.4
patch
4 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.3
patch
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.2
patch
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.5.1
minor
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.4.1
patch
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.4.0
minor
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.3.0
minor
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev | ||
3.2.4
patch
5 CVEs
CVE-2026-40295
GHSA-jp94-3292-c3xv
May 08, 2026
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryWhen the DetailsThe vulnerable code is in
This is passed directly to
The GET timeout path uses By contrast, Devise's Impact
Note: Rails' built-in open-redirect protection does not mitigate this issue. PatchesThis is patched in Devise v5.0.4. Users should upgrade as soon as possible. WorkaroundNone beyond upgrading. If an upgrade is not immediately possible, the same changes from the patch commit can be applied as a monkey-patch in a Rails initializer ( Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 160 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
5.0.3
Fixed in
5.0.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-32700
GHSA-57hq-95w6-v4fc
Mar 17, 2026
Devise has a confirmable "change email" race condition permits user to confirm email they have no access to
Medium
Network
High
Low
None
ImpactA race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the By sending two concurrent email change requests, an attacker can desynchronize the PatchesThis is patched in Devise v5.0.3. Users should upgrade as soon as possible. WorkaroundsApplications can override this specific method from Devise models to force
Note: Mongoid does not seem to respect that Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 159 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
4.7.1
4.7.2
4.7.3
4.8.0
4.8.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.0.rc
5.0.1
5.0.2
Fixed in
5.0.3
References
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2015-8314
GHSA-746g-3gfp-hfhw
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 118 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.2
3.5.3
Fixed in
3.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16109
GHSA-fcjw-8rhj-gwwc
Sep 11, 2019
Authentication Bypass in Devise
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.) Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 145 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.6.0
4.6.1
4.6.2
4.7.0
Fixed in
4.7.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2019-5421
GHSA-73rf-6mrf-759q
Mar 19, 2019
devise Time-of-check Time-of-use Race Condition vulnerability
Medium
Devise ruby gem before 4.6.0 when the Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
+ 141 more Show less
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0
1.0.1
1.0.10
1.0.11
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.pre
1.1.pre2
1.1.pre3
1.1.pre4
1.1.rc0
1.1.rc1
1.1.rc2
1.2.0
1.2.1
1.2.rc
1.2.rc2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.1
1.4.2
1.4.3
1.4.5
1.4.7
1.4.8
1.4.9
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.5.3
1.5.4
2.0.0
2.0.0.rc
2.0.0.rc2
2.0.1
2.0.2
2.0.4
2.0.5
2.0.6
2.1.0
2.1.0.rc
2.1.0.rc2
2.1.2
2.1.3
2.1.4
2.2.0
2.2.0.rc
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.0.0
3.0.0.rc
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0.rc2
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.4.0
3.4.1
3.5.1
3.5.10
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
Fixed in
4.6.0
References Updated Nov 30, 2024 · Source: OSV.dev |